﻿using System;
using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using HZ.MBSM.DBUtility;

public partial class Manage_AddTouSu : System.Web.UI.Page
{
    string AccountIdAnswer,AnswerMan;
    protected void Page_Load(object sender, EventArgs e)
    {

        AccountIdAnswer = SysFun.IsSQL(Request["AccountIdAnswer"]);
        AnswerMan = SysFun.IsSQL(Request["TouSuRen"]);
        SuperViser.Text = AnswerMan;

    }
    protected void sub_Click(object sender, EventArgs e)
    {
        Int64 AccountId;
        string strSql, strMsg;
        HZ.MBSM.Model.Account _Account = (HZ.MBSM.Model.Account)Session["Account"];
        if (_Account != null)
        {
            AccountId = SysFun.ToLong(_Account.AccountId);

            if (txtContent.Text.Trim().Length > 0 && txtTitle.Text.Trim().Length > 0)
            {
                if (txtTitle.Text.IndexOf("'") == -1 && txtContent.Text.IndexOf("'") == -1)
                {

                    strSql = "insert into tousu(AnswerId,CreateDate,AccountId,Title,Content) values (" + SysFun.ToInt(AccountIdAnswer) + ",'" + SysFun.ToTrim(DateTime.Now) + "','" + SysFun.ToTrim(AccountId) + "','" + SysFun.ToTrim(txtTitle.Text) + "','" + SysFun.ToTrim(txtContent.Text) + "')";
                    Db db = new Db();
                    db.Command(strSql);
                    strMsg = "提交成功！";
                    db.Close();
                    

                }
                else
                {
                    strMsg = "输入的文本中含有非法字符如：’！";
                }

            }
            else
            {
                strMsg = "提问内容和标题都不能为空！";
            }
            Response.Write("<script language=JavaScript>alert('" + strMsg + "！！！');</script>");
            Response.Write("<script>window.close();</script>");
        }
        else
        {
            Response.Write("<script language=JavaScript>alert('您还未登录，暂时无法留言！！！');</script>");
        }
    }
}
